📦 Ax1803 Firmware

by Tenda

🔍 What is Ax1803 Firmware?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-30620

CRITICAL CVSS 9.8 Apr 2, 2024

This vulnerability in Tenda AX1803 routers allows remote attackers to execute arbitrary code via a stack overflow in the serviceName parameter. Attackers can potentially take full control of affected ...

CVE-2023-51962

CRITICAL CVSS 9.8 Jan 10, 2024

This vulnerability allows remote attackers to execute arbitrary code on Tenda AX1803 routers by exploiting a stack overflow in the setIptvInfo function. Attackers can send specially crafted requests t...

CVE-2023-51968

CRITICAL CVSS 9.8 Jan 10, 2024

This vulnerability allows remote attackers to execute arbitrary code on Tenda AX1803 routers via a stack overflow in the getIptvInfo function. Attackers can exploit this by sending specially crafted r...

CVE-2023-51970

CRITICAL CVSS 9.8 Jan 10, 2024

This vulnerability allows remote attackers to execute arbitrary code on Tenda AX1803 routers via a stack overflow in the formSetIptv function. Attackers can exploit this by sending specially crafted r...

CVE-2023-51954

CRITICAL CVSS 9.8 Jan 10, 2024

CVE-2023-51954 is a critical stack overflow vulnerability in Tenda AX1803 routers that allows remote attackers to execute arbitrary code by sending specially crafted requests to the iptv.stb.port para...

CVE-2023-51956

CRITICAL CVSS 9.8 Jan 10, 2024

This vulnerability allows remote attackers to execute arbitrary code on Tenda AX1803 routers via a stack overflow in the formSetIptv function. Attackers can exploit this by sending specially crafted r...

CVE-2023-51958

CRITICAL CVSS 9.8 Jan 10, 2024

This vulnerability allows remote attackers to execute arbitrary code on Tenda AX1803 routers via a stack overflow in the formGetIptv function. Attackers can exploit this by sending specially crafted r...

CVE-2023-51960

CRITICAL CVSS 9.8 Jan 10, 2024

This vulnerability allows remote attackers to execute arbitrary code on Tenda AX1803 routers via a stack overflow in the formGetIptv function. Attackers can exploit this by sending specially crafted r...

CVE-2023-51964

CRITICAL CVSS 9.8 Jan 10, 2024

This vulnerability allows remote attackers to execute arbitrary code on Tenda AX1803 routers by exploiting a stack overflow in the setIptvInfo function. Attackers can send specially crafted requests t...

CVE-2023-51952

CRITICAL CVSS 9.8 Jan 10, 2024

This vulnerability allows remote attackers to execute arbitrary code on Tenda AX1803 routers via a stack overflow in the formSetIptv function. Attackers can exploit this by sending specially crafted r...

CVE-2023-51961

CRITICAL CVSS 9.8 Jan 10, 2024

This vulnerability allows remote attackers to execute arbitrary code on Tenda AX1803 routers by exploiting a stack overflow in the formGetIptv function. Attackers can send specially crafted requests t...

CVE-2023-51971

CRITICAL CVSS 9.8 Jan 10, 2024

CVE-2023-51971 is a critical stack overflow vulnerability in Tenda AX1803 routers that allows remote attackers to execute arbitrary code by sending specially crafted requests to the adv.iptv.stbpvid p...

CVE-2023-49044

CRITICAL CVSS 9.8 Nov 27, 2023

A stack overflow vulnerability in Tenda AX1803 routers allows remote attackers to execute arbitrary code by sending specially crafted requests to the ssid parameter in the form_fast_setting_wifi_set f...

CVE-2023-49040

CRITICAL CVSS 9.8 Nov 27, 2023

This vulnerability allows remote attackers to execute arbitrary code on Tenda AX1803 routers by sending specially crafted requests to the adslPwd parameter. Attackers can gain full control of affected...

CVE-2023-49043

CRITICAL CVSS 9.8 Nov 27, 2023

A buffer overflow vulnerability in Tenda AX1803 routers allows remote attackers to execute arbitrary code by sending specially crafted data to the wpapsk_crypto parameter. This affects all users runni...

CVE-2026-1329

HIGH CVSS 8.8 Jan 22, 2026

A stack-based buffer overflow vulnerability in Tenda AX1803 routers allows remote attackers to execute arbitrary code by manipulating parameters in the guest WiFi configuration function. This affects ...

CVE-2025-70648

HIGH CVSS 7.5 Jan 21, 2026

Tenda AX1803 routers running firmware v1.0.0.1 contain a stack overflow vulnerability in the security_5g parameter handling. Attackers can send crafted requests to trigger a Denial of Service (DoS), p...

CVE-2025-70646

HIGH CVSS 7.5 Jan 21, 2026

Tenda AX1803 routers running firmware v1.0.0.1 contain a stack overflow vulnerability in the security parameter handling. Attackers can send crafted requests to trigger a denial of service, potentiall...

CVE-2025-70651

HIGH CVSS 7.5 Jan 21, 2026

A stack overflow vulnerability in Tenda AX-1803 routers allows attackers to cause Denial of Service (DoS) by sending specially crafted requests to the SSID parameter. This affects users running Tenda ...

CVE-2025-63458

HIGH CVSS 7.5 Oct 31, 2025

Tenda AX-1803 routers version 1.0.0.1 contain a stack overflow vulnerability in the timeZone parameter of the form_fast_setting_wifi_set function. Attackers can exploit this to cause Denial of Service...

CVE-2024-4236

HIGH CVSS 8.8 Apr 26, 2024

This critical vulnerability in Tenda AX1803 routers allows remote attackers to execute arbitrary code via a stack-based buffer overflow in the DDNS configuration function. Attackers can exploit this b...

CVE-2023-49047

HIGH CVSS 7.5 Nov 27, 2023

This vulnerability allows remote attackers to execute arbitrary code on Tenda AX1803 routers by exploiting a stack overflow in the device name setting function. Attackers can send specially crafted re...

CVE-2023-48109

HIGH CVSS 7.5 Nov 20, 2023

This vulnerability in Tenda AX1803 routers allows attackers to trigger a heap overflow via the deviceId parameter in the saveParentControlInfo function. Attackers can exploit this to cause a Denial of...

CVE-2023-48111

HIGH CVSS 7.5 Nov 20, 2023

This vulnerability in Tenda AX1803 routers allows attackers to trigger a stack overflow via the time parameter in the saveParentControlInfo function, leading to Denial of Service (DoS). Attackers can ...

CVE-2022-30040

HIGH CVSS 7.5 May 11, 2022

CVE-2022-30040 is a buffer overflow vulnerability in Tenda AX1803 routers that allows attackers to cause denial of service by sending specially crafted HTTP requests to the SetSysTimeCfg endpoint. Att...